Expert in Secure Development

Reposted 2 Days Ago
Be an Early Applicant
Brussels
In-Office
Expert/Leader
Information Technology • Consulting
The Role
The Expert in Secure Development will ensure security in software processes through penetration testing, vulnerability analysis, and guidance on remediation for the AFIS application.
Summary Generated by Built In

COSMOTE Global Solutions, part of the OTE Group of Companies, is a leading provider of ICT Solutions and Services, specializing in various areas such as Cloud, Data Centre operations, Networking, Cybersecurity, and more.

As an Expert in Secure Development, you will play a critical role in enhancing the security of our software development processes, ensuring that all applications are built with a strong security posture.

Responsibilities:

  • Perform a white-box penetration test of the AFIS application, using full access to source code, documentation, system configuration, and user accounts with varying privilege levels.
  • Design and execute authenticated attack scenarios for multiple predefined user roles, focusing on privilege escalation, horizontal access abuse, and misuse of authenticated functionalities.
  • Apply a structured penetration testing methodology, based on PTES (Penetration Testing Execution Standard) or an equivalent industry-accepted approach, ensuring completeness and repeatability of the test process.
  • Conduct all tests in alignment with the OWASP Testing Checklist, covering the required categories such as authentication, authorization, session management, input validation, error handling, and business logic testing.
  • Analyse identified vulnerabilities, exploitation paths, and systemic weaknesses, and evaluate their impact, likelihood, and relevance to the AFIS security posture.
  • Document all findings in a comprehensive PDF report, including technical descriptions, reproduction steps, risk severity ratings, affected components, and recommended remediation actions.
  • Register all discovered defects as bugs in the AFIS Ticketing platform, using the agreed-upon template and severity classification, ensuring traceability to the penetration test results.
  • Provide guidance to the AFIS team on remediation approaches, mitigation strategies, and secure alternatives for high-risk issues.
  • Participate in review or clarification meetings, on request, to walk through findings, exploitation steps, and recommended fixes with stakeholders.

Requirements
  • Master’s Degree on It or a related field
  • Minimum 8 years of experience in offensive security testing of Web Applications and Infrastructure technologies on a relevant technology stack (Java, Linux, Oracle/Postgres)
  • Deep understanding of penetration testing methodologies such as PTES, OWASP Testing Guide, NIST SP 800-115, and ISSAF.
  • Extensive knowledge of OWASP Top 10, OWASP ASVS, CWE, and common vulnerability classes.
  • Familiarity with modern application architectures (web, API, client–server, microservices).
  • Knowledge of secure software development practices and common coding pitfalls.
  • Understanding of authentication and authorization models, including role-based access control, session management, and token-based authentication.
  • Knowledge of network protocols, encryption, TLS, certificates, and secure communication patterns.
  • Strong understanding of application data flows, business logic, and trust boundaries.
  • Expertise in exploit development concepts, payload crafting, and evasion techniques (where applicable in a white-box context).
  • Knowledge of logging and monitoring mechanisms, audit trails, and security-relevant events.
  • Understanding of the AFIS application architecture (once documentation is provided).
  • Familiarity with the programming languages, frameworks, and libraries used in the AFIS code base (Java, Spring Boot, React, Python).
  • Knowledge of identity and access management technologies affecting authenticated scenarios.
  • Experience with issue tracking platforms, specifically Gitlab, for accurate defect reporting.
  • Understanding of the AFIS application architecture (once documentation is provided).
  • Familiarity with the programming languages, frameworks, and libraries used in the AFIS code base.
  • Knowledge of identity and access management technologies affecting authenticated scenarios.
  • Experience with issue tracking platforms, specifically Jira, for accurate defect reporting.
  • Ability to perform white-box testing, including code-assisted analysis and configuration review.
  • Expertise in authenticated testing, including session manipulation, impersonation, and privilege escalation attempts.
  • Ability to identify security flaws in business logic, not just technical layers.
  • Skills in dynamic analysis, static analysis, and manual testing techniques.
  • Proficiency in using penetration testing tools, such as:
    • Burp Suite Pro
    • OWASP ZAP
    • Postman / API testing tools
    • Browser DevTools
    • Source code review tools (static analyzers when available)
  • Ability to create and execute realistic attack chains based on combined vulnerabilities.
  • Ability to understand, speak and write French (C2); Dutch (B1) will be an advantage.

Mandatory Certifications:

Offensive Security Certified Professional (OSCP)

Top Skills

Burp Suite Pro
Java
Linux
Oracle
Owasp Zap
Postgres
Postman
Python
React
Spring Boot
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Brussels
17 Employees

What We Do

COSMOTE Global Solutions, as a member of OTE Group of Companies, is an ICT Systems Integrator delivering a broad range of ICT Solutions and Services.

CGS provides a broad range of ICT Services focusing on: Cloud, Data Centre operations, Networking, Cybersecurity, BI and Data Warehouse, Big Data, Service Desk, Proactive Monitoring, Operations and Support, Service Management, Project and Programme Management, and Professional Services.


OTE Group:

OTE Group is the largest technology provider in Greece. It is one of the top three listed companies with respect to capitalization, in the Athens Stock Exchange. Deutsche Telekom holds 46.9% of OTE’s share capital and the Greek State holds 5.6%. Find More about OTE Group

Our Vision:

We digitize societies so that everyone can live and enjoy at the fullest all possibilities offered now while also building on them for a better tomorrow.

Our Mission:

• We bring the best communication services to our customers
• We connect people
• We entertain
• We help businesses grow.
• We are leaders, pioneers, pillar of the economy and society
• With passion, faith and commitment
• We constantly strive to become better on all fronts
• We have a positive impact on society and the environment

Similar Jobs

ServiceNow Logo ServiceNow

Lead Sales BDM (Public Sector)

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Brussels, BEL
28000 Employees

Wise Logo Wise

Product Compliance and Risk Lead - Fincrime Europe

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
Brussels, BEL
8000 Employees

Capco Logo Capco

Consultant

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
Brussels, BEL
6000 Employees

ServiceNow Logo ServiceNow

Enterprise Account Executive

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
Brussels, BEL
28000 Employees

Similar Companies Hiring

Scrunch AI Thumbnail
Software • SEO • Marketing Tech • Information Technology • Artificial Intelligence
Salt Lake City, Utah
Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account